Data Processing Addendum
Version Data_Processing_Addendum_v1.0Effective July 20, 2026Current policy
On this page
ChemCal Pro Data Processing Addendum
Effective date: July 16, 2026
Last updated: July 17, 2026
Document ID: CCP-LEGAL-DPA-001
Version: 1.1
This Data Processing Addendum (“DPA”) forms part of the ChemCal Pro Terms of Service, an order form, or another agreement between ChemCal Pro LLC (“ChemCal Pro”) and Customer governing the Service (“Agreement”). Capitalized terms not defined here have the meanings in the Agreement.
1. Definitions
- Applicable Data Protection Law means privacy and data-protection law applicable to the Processing of Customer Personal Data, including, where applicable, the GDPR, UK GDPR, Canada’s PIPEDA, Australia’s Privacy Act and Australian Privacy Principles, India’s Digital Personal Data Protection Act and rules as in force, and applicable U.S. state privacy laws.
- Customer Personal Data means Personal Data Processed by ChemCal Pro on Customer’s behalf through the Service. It excludes Personal Data for which ChemCal Pro determines the purposes and means as an independent Controller, such as limited contracting, billing, fraud-prevention, security, legal-compliance, and claims data.
- Controller, Processor, Data Subject, Personal Data, Process, Processing, and Supervisory Authority have the meanings under Applicable Data Protection Law. Business, Consumer, Service Provider, Sell, and Share have the meanings under applicable U.S. state privacy law.
- Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It excludes unsuccessful attempts that do not compromise Customer Personal Data, such as blocked scans or failed login attempts.
- Subprocessor means a third party engaged by ChemCal Pro to Process Customer Personal Data on Customer’s behalf.
2. Scope, roles, and duration
- Customer is the Controller or Business and ChemCal Pro is the Processor or Service Provider for Customer Personal Data.
- Each party will comply with Applicable Data Protection Law as it applies to that party’s role.
- Processing continues for the Agreement term and any limited period necessary for return, deletion, legal retention, security, or transition.
- Annex I describes the subject matter, nature, purpose, data categories, and Data Subjects.
- ChemCal Pro acts as an independent Controller for limited Personal Data used for contracting, billing, accounting, tax, fraud prevention, service security, direct service communications, legal compliance, and establishment or defense of claims. The Privacy Policy governs that Processing.
3. Customer instructions and responsibilities
- The Agreement, this DPA, Customer’s configuration and use of the Service, and documented instructions from an authorized Company Admin constitute Customer’s documented instructions.
- ChemCal Pro will Process Customer Personal Data only on documented instructions, including for transfers, unless law requires otherwise. If legally permitted, ChemCal Pro will notify Customer before legally required Processing.
- Customer is responsible for the lawfulness, fairness, accuracy, and quality of Customer Personal Data and instructions, including required notices, consents, lawful bases, employment obligations, and rights of Authorized Users.
- Customer will not instruct ChemCal Pro to violate law or Process unnecessary sensitive, health, biometric, pest-company customer/job, pesticide-application, or other out-of-scope information.
- If ChemCal Pro reasonably believes an instruction violates Applicable Data Protection Law, it may suspend the affected Processing and notify Customer, unless prohibited by law.
4. Confidentiality and personnel
- ChemCal Pro will ensure persons authorized to Process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty.
- Access will be limited to persons who need it to provide, secure, maintain, troubleshoot, or support the Service; comply with law; or address an authorized request.
- ChemCal Pro will provide appropriate privacy and security direction to personnel with access.
5. Security
- Taking account of the state of the art, implementation costs, nature, scope, context, and purposes of Processing, and risk to individuals, ChemCal Pro will maintain appropriate technical and organizational measures designed to protect Customer Personal Data.
- The current security-control schedule is in Annex II.
- Customer is responsible for configuring roles, protecting credentials and devices, removing users promptly, verifying Customer content, and using Service security features appropriately.
- ChemCal Pro may update security measures without materially decreasing the overall protection of Customer Personal Data.
- ChemCal Pro does not represent that it holds a certification or audit report unless expressly stated in a current Security Addendum.
6. Subprocessors
- Customer provides general written authorization for the Subprocessors listed in Annex III and the then-current public Subprocessor List.
- ChemCal Pro will require each Subprocessor to protect Customer Personal Data through written terms that are materially protective of the obligations applicable to the Subprocessor’s Processing.
- ChemCal Pro remains responsible to Customer for a Subprocessor’s performance to the extent required by Applicable Data Protection Law and the Agreement.
- ChemCal Pro will provide at least 30 days’ prior notice of a material new Subprocessor where reasonably practicable. Customer may object during that period on reasonable documented data-protection grounds.
- The parties will work in good faith to address a valid objection. If no commercially reasonable alternative is available, Customer may terminate the affected Service before the Subprocessor begins Processing. This is Customer’s sole remedy for a properly raised Subprocessor objection, without limiting mandatory rights.
7. Data Subject requests
- Taking account of the nature of Processing, ChemCal Pro will provide reasonable assistance for Customer to respond to verified requests to exercise Data Subject rights.
- If ChemCal Pro receives a request relating primarily to Customer Personal Data, ChemCal Pro will refer the requester to Customer where appropriate and will not independently respond except on Customer’s instruction or as required by law.
- Customer is responsible for determining whether and how to fulfill a request. ChemCal Pro may charge reasonable fees for extraordinary assistance not included in the Service, after notice, unless law requires assistance without charge.
8. Security Incidents
- ChemCal Pro will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data.
- Notice will include information reasonably available about the nature of the incident, affected data and individuals, likely consequences, mitigation, and a contact for follow-up. Information may be provided in phases.
- ChemCal Pro will take reasonable steps to contain, investigate, mitigate, and remediate the Security Incident and will reasonably cooperate with Customer’s legally required response.
- ChemCal Pro’s notice is not an admission of fault or liability. Customer is responsible for notices to individuals and regulators unless law places that duty directly on ChemCal Pro.
- Customer must maintain current security contacts and promptly notify ChemCal Pro of suspected compromise involving Customer accounts.
9. DPIAs, consultations, and compliance assistance
Taking account of the nature of Processing and information available, ChemCal Pro will provide reasonable assistance with Customer’s obligations concerning security, breach notifications, data-protection impact assessments, and prior consultation with Supervisory Authorities. Extraordinary assistance may be subject to reasonable fees after notice.
10. Government and legal requests
- ChemCal Pro will evaluate requests for Customer Personal Data and disclose only where it reasonably believes disclosure is legally required.
- Where legally permitted, ChemCal Pro will notify Customer before disclosure and provide reasonable information for Customer to seek protection.
- ChemCal Pro will use reasonable efforts to challenge overbroad or unlawful requests where appropriate in the circumstances.
11. Return, export, deletion, and retention
- During the Agreement term, Customer may access Customer Personal Data through available Service functionality.
- Upon termination or Customer’s authenticated written request, and at Customer’s choice where required by Applicable Data Protection Law, ChemCal Pro will return or delete available Customer Personal Data using the Service functionality and documented operational procedures then available, unless applicable law requires continued storage.
- Return and deletion remain subject to identity and authority verification, security requirements, legal holds, preservation of disputes, technical feasibility, provider-controlled backup and log cycles, and the permitted retention described in Section 11.4.
- ChemCal Pro may retain limited records required or permitted for legal acceptance, contract authority, billing, tax, accounting, fraud prevention, security, dispute preservation, verification history, audit integrity, and legal compliance. Retained Personal Data will remain protected, access-restricted, and used only for the retention purpose.
- Customer Personal Data contained in provider-managed backups or infrastructure logs will not be used for ordinary business purposes and will remain protected until removed through the applicable provider’s operational cycle, except where accessed for security, continuity, recovery, or legal purposes.
- ChemCal Pro may retain irreversibly de-identified data that cannot reasonably identify Customer or a person.
12. Audits and information
- ChemCal Pro will make information reasonably necessary to demonstrate compliance with this DPA available to Customer.
- Customer will first use current security documentation, policies, questionnaires, certifications, or independent reports ChemCal Pro can lawfully provide.
- No more than once annually, and additionally after a substantiated Security Incident or regulator request, Customer may request a reasonable remote audit concerning Customer Personal Data.
- An on-site audit is available only when required by a Supervisory Authority or when documentation and remote review cannot reasonably resolve a material substantiated concern. It must occur during normal business hours, on reasonable notice, under confidentiality, without access to another customer’s information, and without unreasonable disruption.
- Customer bears its audit costs and ChemCal Pro’s reasonable costs for extraordinary assistance unless the audit identifies a material breach by ChemCal Pro.
13. U.S. state service-provider terms
To the extent applicable U.S. state law treats ChemCal Pro as a Service Provider or Processor:
- ChemCal Pro will Process Customer Personal Data only for the limited and specified purposes in the Agreement and Customer instructions.
- ChemCal Pro will not Sell or Share Customer Personal Data, retain/use/disclose it outside the business relationship, or combine it with personal data from another source except as permitted by applicable law and needed to provide or secure the Service.
- Customer may take reasonable steps to verify compliance and may require ChemCal Pro to stop and remediate unauthorized Processing.
- ChemCal Pro will notify Customer if it determines it can no longer meet applicable obligations.
14. International transfers
- Where Customer Personal Data is transferred from the EEA to a country not recognized as adequate and the EU SCCs are required, the 2021 European Commission Standard Contractual Clauses are incorporated by reference using Module Two (Controller to Processor), or Module Three (Processor to Processor) when Customer acts as a Processor.
- For the EU SCCs: Clause 7 (docking) applies; Clause 9 Option 2 (general written authorization) applies with the notice period in Section 6; the optional language in Clause 11 does not apply; Clause 17 Option 1 selects Irish law; and Clause 18 selects the courts of Ireland. Annexes I through III below complete the SCC appendices.
- The competent Supervisory Authority is the authority identified under Clause 13 based on Customer’s establishment, appointed representative, or affected Data Subjects. When the SCCs apply, Customer must identify the applicable authority and its EEA establishment or representative information in the DPA acceptance record or applicable order form.
- For restricted transfers subject to UK data-protection law, the ICO International Data Transfer Addendum to the EU SCCs, version B1.0 in force March 21, 2022, is incorporated. Annex IV completes its Part 1 Tables, and its Part 2 Mandatory Clauses apply without modification except as the approved Addendum permits.
- The parties will reasonably cooperate on transfer risk assessments and supplemental safeguards where required.
- If a transfer mechanism is invalidated, the parties will use an available lawful alternative. ChemCal Pro may suspend the affected transfer if no lawful mechanism is reasonably available.
15. Liability and order of precedence
- Liability under this DPA—including liability arising from a Security Incident, data breach, loss, corruption, unauthorized access, use or disclosure of Customer Personal Data, privacy event, or assistance obligation—is subject to the exclusions, one-month aggregate cap, non-recourse provision, and other limitations in Section 18 of the Terms, except to the extent Applicable Data Protection Law prohibits that limitation.
- If this DPA conflicts with the Agreement concerning Processing of Customer Personal Data, this DPA controls.
- The EU SCCs or UK transfer terms control over conflicting terms to the extent required for the relevant transfer.
16. Term and changes
This DPA terminates when ChemCal Pro no longer Processes Customer Personal Data, except provisions that must survive. ChemCal Pro may update this DPA to address legal or operational changes, but will not materially reduce protection without reasonable notice. Material changes may require Company Admin reacceptance.
Annex I — Parties and processing details
A. Parties and acceptance
Legal identity
Data exporter: Customer legal entity identified in the ChemCal Pro organization account, order form, and DPA acceptance record
Data importer: ChemCal Pro LLC, a Texas limited liability company
Address
Data exporter: Customer address recorded in the organization account, order form, or DPA acceptance record
Data importer: 63 Marino Drive, Missouri City, Texas 77459, United States
Contact
Data exporter: Authorized Company Admin or privacy contact recorded at acceptance
Data importer: info@chemcalpro.com; subject Privacy Request
Role
Data exporter: Controller; or Processor when Customer Processes for another Controller
Data importer: Processor or Subprocessor for Customer Personal Data
Signature/acceptance
Data exporter: Electronic acceptance by an authorized Company Admin, recorded with name, organization, timestamp, Document ID, and version, has the same contractual effect as signature
Data importer: ChemCal Pro’s publication and incorporation of this DPA into the Agreement constitutes acceptance by ChemCal Pro
When the EU SCCs apply, the parties are the data exporter and data importer above. Customer must ensure its recorded identity, contact, role, EEA establishment or representative, and competent Supervisory Authority are complete and current.
B. Description of Processing
Subject matter
Description: Hosting and operation of ChemCal Pro for Customer
Duration
Description: Agreement term plus the limited return, deletion, provider-cycle, legal-retention, and transition periods described in Section 11
Nature
Description: Collection, recording, organization, storage, retrieval, consultation, transmission, display, restriction, support access, deletion, and de-identification
Purpose
Description: Account and organization administration; product/Label/SDS organization; company guidance; calculator creation, verification, and delivery; favorites; security; support; and contracted Service functions
Data Subjects
Description: Company Admins, technicians, invited users, Customer personnel, and individuals communicating with support
Personal Data
Description: Names, emails, authentication/session identifiers, organization/membership roles/statuses/timestamps, actor/audit data, favorites, author/reviewer/verifier data, support communications, and technical/security metadata
Sensitive data
Description: Not intended. Customer must not submit health, biometric, precise location, government identifiers, payment-card data, pest-company customer/job records, or other unnecessary sensitive data
Frequency
Description: Continuous or as initiated by Customer and Authorized Users
Customer instructions
Description: Agreement, configuration, Company Admin actions, and documented support instructions
Annex II — Security-control schedule
ChemCal Pro’s current documented control design includes:
- individual authenticated accounts; no shared generic accounts;
- role-based Company Admin, technician, and platform-administrator permissions;
- organization-level tenant isolation using org_id and database row-level security;
- protected server-side actions for administrative operations;
- private file-storage buckets and time-limited signed URLs for protected files;
- restricted service credentials and separation of client and server credentials;
- separation of development, staging, and production environments;
- staging-first testing and explicit approval for production changes;
- migration, access-control, tenant-isolation, lint, build, and workflow verification appropriate to release risk;
- structured calculator evaluation without raw executable customer code;
- audit events for material administrative and security-sensitive workflows supported by the Service;
- lifecycle states and controlled archive/restore workflows;
- vendor-hosted encryption in transit and at rest according to provider capabilities; and
- incident evidence preservation, rollback awareness, and post-release verification procedures.
Annex III — Authorized Subprocessors
Effective July 16, 2026, the following direct Subprocessors are authorized:
Supabase Pte. Ltd.
Processing purpose: Hosted PostgreSQL database, authentication, private object storage, backend services, backup, and infrastructure security/logging
Customer Personal Data: Account, organization, membership, Customer Content, Label/SDS and calculator metadata, authentication identifiers, files, audit and technical data
Primary processing location: Customer-selected United States project region; limited support and Subprocessor access may occur elsewhere under provider terms
Transfer mechanism where required: Supabase DPA; EU SCCs Modules 2/3 and applicable UK transfer terms
Vercel Inc.
Processing purpose: Application hosting, deployment, content delivery, server-side execution, request handling, and infrastructure/security logging
Customer Personal Data: Requests and responses passing through the application, account/service data in transit, IP address, user agent, request, error, and security metadata
Primary processing location: United States primary compute configuration; global delivery and support locations under provider terms
Transfer mechanism where required: Vercel DPA; EU SCCs Modules 2/3 and UK International Data Transfer Addendum
Customers may subscribe to material new-Subprocessor notices by emailing info@chemcalpro.com with the subject Subscribe — Subprocessor Notices from an authorized Company Admin address. ChemCal Pro will update the Subprocessor List before a newly engaged direct provider begins Processing Customer Personal Data, except where an emergency replacement is reasonably necessary to protect the Service and permitted by Applicable Data Protection Law.
Annex IV — UK International Data Transfer Addendum Tables
Table 1 — Parties and start date
- Start date: the date Customer accepts this DPA or the Agreement incorporating it.
- Exporter: Customer, using the identity, address, contact, and electronic acceptance information in Annex I.A.
- Importer: ChemCal Pro LLC, 63 Marino Drive, Missouri City, Texas 77459, United States; info@chemcalpro.com.
- Signatures: the electronic acceptance method in Annex I.A applies.
Table 2 — Selected SCCs, modules, and clauses
- The Approved EU SCCs are the clauses adopted by Commission Implementing Decision (EU) 2021/914.
- Module Two applies when Customer is a Controller; Module Three applies when Customer is a Processor.
- Clause 7 applies; Clause 9 Option 2 applies with the Section 6 notice period; Clause 11 optional language does not apply.
- Customer Personal Data received from ChemCal Pro is not combined with Personal Data independently collected by ChemCal Pro for a separate purpose, except as permitted by the Agreement and Applicable Data Protection Law.
Table 3 — Appendix information
- Annex I.A supplies the parties and acceptance details.
- Annex I.B supplies the transfer and Processing details.
- Annex II supplies the technical and organizational measures.
- Annex III supplies the Authorized Subprocessor list.
Table 4 — Ending the Addendum
Exporter and Importer may end the Addendum as permitted by Section 19 of the ICO’s approved Mandatory Clauses.
The Mandatory Clauses of the ICO International Data Transfer Addendum, version B1.0 in force March 21, 2022, are incorporated by reference. Privacy requests may be sent to info@chemcalpro.com with the subject Privacy Request; security reports may be sent with the subject Security Report.